๐Ÿ” CVE Alert

CVE-2026-71862

HIGH 7.5

Checkmate: Sensitive Bearer Token Exposure via Public Status Pages When showURL Setting is Enabled

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the unauthenticated GET /api/v1/status-page/:url endpoint to return complete monitor objects from server/src/controllers/statusPageController.ts. The response includes the secret field used by HttpProvider.ts as an HTTP Authorization credential, even though BaseStatusPage.tsx does not display that value, allowing visitors to extract credentials from the JSON response and use them against monitored services. This issue is fixed in version 3.9.2.

CWE CWE-200 CWE-522
Vendor bluewave-labs
Product checkmate
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for bluewave-labs checkmate

Be the first to know when new high vulnerabilities affecting bluewave-labs checkmate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

bluewave-labs / Checkmate
>= 3.3.0, < 3.9.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bluewave-labs/Checkmate/security/advisories/GHSA-3m74-8cg9-rp8j github.com: https://github.com/bluewave-labs/Checkmate/pull/3758 github.com: https://github.com/bluewave-labs/Checkmate/commit/cc1814f507041bb0f64845bed5d5442c21e920f2 github.com: https://github.com/bluewave-labs/Checkmate/releases/tag/v3.9.2